CVE-2026-80528
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
26/08/2026
Última modificación:
27/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ceph: avoid fs reclaim while using current->journal_info<br />
<br />
handle_reply() stores a `ceph_mds_request` pointer in<br />
`current->journal_info` while filling the inode and dentry cache from<br />
an MDS reply.<br />
<br />
An allocation in this section can enter direct reclaim and prune<br />
dentries from another filesystem. If this dirties an ext4 inode, ext4<br />
starts a JBD2 transaction. JBD2 interprets the Ceph request in<br />
`current->journal_info` as a journal handle and dereferences the<br />
request&#39;s `r_tid` as `h_transaction`, causing a kernel crash, e.g.:<br />
<br />
Unable to handle kernel paging request at virtual address 00000000077b4818<br />
[...]<br />
Internal error: Oops: 0000000096000004 [#1] SMP<br />
Modules linked in:<br />
CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G W 6.18.38-i3 #1113 NONE<br />
[...]<br />
Workqueue: ceph-msgr ceph_con_workfn<br />
pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)<br />
pc : jbd2__journal_start+0x2c/0x208<br />
lr : __ext4_journal_start_sb+0x100/0x178<br />
[...]<br />
Call trace:<br />
jbd2__journal_start+0x2c/0x208 (P)<br />
__ext4_journal_start_sb+0x100/0x178<br />
ext4_dirty_inode+0x3c/0x90<br />
__mark_inode_dirty+0x58/0x400<br />
iput.part.0+0x2b0/0x370<br />
iput+0x18/0x30<br />
dentry_unlink_inode+0xc0/0x158<br />
__dentry_kill+0x80/0x250<br />
shrink_dentry_list+0x90/0x130<br />
prune_dcache_sb+0x60/0x98<br />
super_cache_scan+0xe8/0x190<br />
do_shrink_slab+0x174/0x388<br />
shrink_slab+0xd8/0x4c0<br />
shrink_node+0x31c/0x908<br />
do_try_to_free_pages+0xd0/0x508<br />
try_to_free_pages+0x11c/0x238<br />
__alloc_frozen_pages_noprof+0x4d0/0xdd0<br />
__folio_alloc_noprof+0x18/0x70<br />
__filemap_get_folio+0x248/0x440<br />
ceph_readdir_prepopulate+0x570/0x9e8<br />
mds_dispatch+0x1424/0x1ba0<br />
ceph_con_process_message+0x74/0xa0<br />
ceph_con_v1_try_read+0x3a0/0x1510<br />
ceph_con_workfn+0x260/0x460<br />
<br />
Enter a scoped NOFS allocation context and leave it after clearing<br />
`journal_info`. This prevents filesystem reclaim from recursing into<br />
another filesystem while the field contains Ceph-private data.
Impacto
Puntuación base 3.x
9.80
Gravedad 3.x
CRÍTICA
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/00c12f57a87f537fa8779258fb3a03003a99963e
- https://git.kernel.org/stable/c/47b745747b3aa39064724a642884f9df924ddf20
- https://git.kernel.org/stable/c/4dbb2c02558e71f93510a6461d7e798b67426b49
- https://git.kernel.org/stable/c/5b602344a49e039e792ce5a8923bcc61412ee134
- https://git.kernel.org/stable/c/79d95b43ca090426399651ed580dd9bf2db36ab8
- https://git.kernel.org/stable/c/b6a0989613072499633e761a1536428a466de7d3
- https://git.kernel.org/stable/c/c8a21660c3b90864c391164eea5622e7b5b2897c
- https://git.kernel.org/stable/c/ca5fa2380dd90a0adb01580fa6225025351a90f6



